Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

Klaralven

(7,510 posts)
39. SolarWinds Orion agent requirements
Mon Dec 14, 2020, 01:12 AM
Dec 2020
Account Privileges

If you want to deploy agents from the Orion server, the following requirements must be met.

Windows
The account used for remote deployment must have access to the administrative share on the target computer: admin$temp.
User Account Control (UAC) must either be disabled on the target computer, or the built-in Administrator account must be used.
You may need to disable UAC remote restrictions.
Other remote or mass deployment methods do not have the same requirements.

Linux/Unix
An account that can connect remotely through SSH.
An account that can install software and create a user and group.
See Credentials and privileges used on Linux/Unix-based computers for more information.

To deploy a Linux/Unix agent via pull deployment, make sure that the following conditions are met:

Orion Web Console must be accessible from the target Linux computer.
Pull deployment uses wget, curl, or perl to download the installation files from the chosen polling engine.

Agent port requirements
The following ports need to be open both to deploy and to update Orion Agents:

Target computer where the agent is deployed
Server hosting the Orion Platform polling engine
Local agent ports

(followed by quite a list of open ports)

FIPS Support
Starting with Orion Platform 2020.2, Orion Agents support FIPS.

To run FIPS-compliant Orion Agents, enable FIPS on the target computer. FIPS is configured both on the main polling engine and on the polled agent computer so all communication between them is FIPS-compliant.

Remote deployment in FIPS mode is disabled. To run Orion Agents in FIPS-compliant mode, deploy agents manually (Windows or Linux/Unix).

(manual agent deployment would be labor intensive, so FIPS support probably not much used - too bad)

https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/core-agent-requirements-sw476.htm

K&R. A Cyber Pearl Harbor. bronxiteforever Dec 2020 #1
Solar Winds gave the Russian's Root Access ! My Pet Orangutan Dec 2020 #2
Jesus... Volaris Dec 2020 #9
I'm thinking is regarded as Ultra-Secure. My Pet Orangutan Dec 2020 #10
I guess theres that small silver lining. Still.. Volaris Dec 2020 #11
Interesting. Did not know that about DoD. bronxiteforever Dec 2020 #14
Anything that technically funnels down to a single pinch point can never be secure. Blue_true Dec 2020 #16
UNIX/TCP/IP is disributed - there is no overriding authority. My Pet Orangutan Dec 2020 #19
Wouldn't the function performed make it a technical pinch point? Blue_true Dec 2020 #22
A quasi pinch point - My Pet Orangutan Dec 2020 #23
I know of one company that won't put anything critical on a connected system. Blue_true Dec 2020 #24
Northram Gurthrop does not put the Crown Jewels online. My Pet Orangutan Dec 2020 #27
A final explanation - when you have a quasi pinch point like Solar Wind My Pet Orangutan Dec 2020 #30
Look like the Russian hackers did just what you pointed out. Blue_true Dec 2020 #34
The reason there is no overriding authority is the system was designed My Pet Orangutan Dec 2020 #25
Why wouldn't there be restricted "roles" that only allow monitoring privileges crimycarny Dec 2020 #33
SolarWinds Orion agent requirements Klaralven Dec 2020 #39
Seems like Trump's moves of late have quite a nefarious lean. Like the replacement of key positions The Wielding Truth Dec 2020 #29
+1 exactly. bronxiteforever Dec 2020 #31
Where is the response from the White House? onecaliberal Dec 2020 #3
'President Putin was extremely strong and powerful in his denials' My Pet Orangutan Dec 2020 #4
I mean, I don't know why he wouldn't be. onecaliberal Dec 2020 #7
President Putin, did you want President Trump to win the election? Kid Berwyn Dec 2020 #15
He fired Krebs. WH response started this, probably soothsayer Dec 2020 #26
It's not like dump can be bothered to care. onecaliberal Dec 2020 #32
Almost seems like I've been... stillcool Dec 2020 #5
This message was self-deleted by its author My Pet Orangutan Dec 2020 #6
Trump let them in the back door jpak Dec 2020 #8
And who was it that fired DHS Cyber Chief Chris Krebs? Resistance1 Dec 2020 #12
I think Krebs may have been in on it. LuvLoogie Dec 2020 #13
Tonight - Krebs will be very glad to be outta there - My Pet Orangutan Dec 2020 #17
I wouldn't be surprised if/when trump blames Krebs. LuvLoogie Dec 2020 #21
he's around... stillcool Dec 2020 #18
And Trump wanted to form a joint cyber security unit with Russia. TubbersUK Dec 2020 #20
Wow. Just wow.... and they wonder why we are always "negative" about this PT Barnum.. The Wielding Truth Dec 2020 #28
Reuters link: Qutzupalotl Dec 2020 #35
Russia. Putin is pos. The sooner that psychopath dies, the better. 58Sunliner Dec 2020 #36
Fireye having their own hacking testing tools to be benld74 Dec 2020 #37
Story a few years ago that Putin had ordered all top secret info in Russia to be on paper only. Midnight Writer Dec 2020 #38
So much for auditing, intrusion and network detection software that are best practices. TheBlackAdder Dec 2020 #40
Latest Discussions»General Discussion»Russians hacked server ca...»Reply #39